D-Link DAP-1360 webproc COMM_MakeCustomMsg Stack-based Buffer Overflow Remote Code Execution Vulnerability
CVE-2023-32144
8.8HIGH
Summary
The D-Link DAP-1360 is susceptible to a stack-based buffer overflow that occurs when handling requests made to the /cgi-bin/webproc endpoint. This vulnerability arises from inadequate validation of user-supplied data length before it is copied to a fixed-length stack-based buffer. Network-adjacent attackers can exploit this flaw to execute arbitrary code on affected devices without requiring any form of authentication, potentially compromising the system at the root level.
Affected Version(s)
DAP-1360 6.14B01 EU HOTFIX
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved